Welcome to our

Cyber Security News Aggregator

.

Cyber Tzar

provide a

cyber security risk management

platform; including automated penetration tests and risk assesments culminating in a "cyber risk score" out of 1,000, just like a credit score.

“Vibe Hacking”: Abusing Developer Trust in Cursor and VS Code Remote Development

published on 2025-08-18 15:51:45 UTC by /u/thaidn_
Content:

In a recent red team engagement, the client's attack surface was so well-defended that after months of effort, the only system we managed to compromise was a lone server, which was apparently isolated from the rest of the network. Or so we thought.

One developer had been using that server for remote development with Cursor. This setup is becoming increasingly popular: developers run AI agents remotely to protect their local machines.

But when we dug deeper into how Cursor works, we discovered something unsettling. By pivoting through the remote server, we could actually compromise the developer's local machine.

This wasn't a Cursor-specific flaw. The root cause lies in the Remote-SSH extension that Cursor inherits directly from VS Code. Which means the attack path we uncovered could extend across the entire VS Code remote development ecosystem, putting any developer who connects to an untrusted server at risk.

For the details, check out our blog post. Comments are welcome! If you enjoy this kind of work, we're hiring!

submitted by /u/thaidn_
[link] [comments]
Article: “Vibe Hacking”: Abusing Developer Trust in Cursor and VS Code Remote Development - published 2 months ago.

https://www.reddit.com/r/netsec/comments/1mtpvuu/vibe_hacking_abusing_developer_trust_in_cursor/   
Published: 2025 08 18 15:51:45
Received: 2025 08 18 16:20:15
Feed: /r/netsec - Information Security News and Discussion
Source: /r/netsec - Information Security News and Discussion
Category: Cyber Security
Topic: Cyber Security
Views: 7

Custom HTML Block

Click to Open Code Editor